Fix sensitive data exposure in Baremetal PING PXE resource logs (#13298)#13668
Fix sensitive data exposure in Baremetal PING PXE resource logs (#13298)#13668DaanHoogland wants to merge 1 commit into
Conversation
SSHCmdHelper.sshExecuteCmdOneShot only redacted logged commands by splitting on the literal keystore filename "cloud.jks", which never appears in baremetal PXE commands. As a result, CIFS storage passwords and raw VM user-data/SSH keys built by BaremetalPingPxeResource were logged in plaintext at debug level. Add maskedCmd-accepting overloads to SSHCmdHelper so callers can supply an already-redacted command for logging, and use them in BaremetalPingPxeResource for the CIFS password and VM user-data code paths, including the failure messages returned in the Answer objects. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## 4.20 #13668 +/- ##
=========================================
Coverage 16.26% 16.26%
- Complexity 13435 13437 +2
=========================================
Files 5667 5667
Lines 500731 500769 +38
Branches 60803 60803
=========================================
+ Hits 81430 81448 +18
- Misses 410197 410215 +18
- Partials 9104 9106 +2
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Pull request overview
Addresses a sensitive logging exposure in the baremetal PING PXE plugin by allowing callers to provide a pre-redacted command string for logging, preventing secrets (CIFS password, VM user-data/SSH keys) from being logged in plaintext.
Changes:
- Added
maskedCmd-accepting overloads inSSHCmdHelperand centralized command selection viagetCmdForLogging. - Updated
BaremetalPingPxeResourceto pass masked variants of sensitive SSH commands and to return masked commands in failureAnswermessages. - Added unit tests covering
getCmdForLoggingbehavior with and without a provided mask.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| utils/src/test/java/com/cloud/utils/ssh/SSHCmdHelperTest.java | Adds unit coverage for masked vs fallback command logging. |
| utils/src/main/java/com/cloud/utils/ssh/SSHCmdHelper.java | Introduces masked-command overloads and shared logging sanitization helper. |
| plugins/hypervisors/baremetal/src/main/java/com/cloud/baremetal/networkservice/BaremetalPingPxeResource.java | Uses masked commands for CIFS password and VM user-data SSH execution and error messages. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| if (maskedCmd != null) { | ||
| return maskedCmd; | ||
| } | ||
| return cmd.split(KeyStoreUtils.KS_FILENAME)[0]; |


Description
SSHCmdHelper.sshExecuteCmdOneShot only redacted logged commands by splitting on the literal keystore filename "cloud.jks", which never appears in baremetal PXE commands. As a result, CIFS storage passwords and raw VM user-data/SSH keys built by BaremetalPingPxeResource were logged in plaintext at debug level.
Add maskedCmd-accepting overloads to SSHCmdHelper so callers can supply an already-redacted command for logging, and use them in BaremetalPingPxeResource for the CIFS password and VM user-data code paths, including the failure messages returned in the Answer objects.
This PR...
Fixes: #13298
Types of changes
Feature/Enhancement Scale or Bug Severity
Feature/Enhancement Scale
Bug Severity
Screenshots (if appropriate):
How Has This Been Tested?
How did you try to break this feature and the system with this change?